IP Library Granted Patent US 12,526,210
Granted Patent B2
US 12,526,210 · App. 18/039,877 · Granted Jan 13, 2026

Network interface supporting time sensitive networks and MACsec protection

Inventor: Maksym Demchenko (Eindhoven, NL)
Assignee: Rambus Inc.
H04L43/026H04L47/245H04L47/28H04L63/20
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,526,210
App. No.
18/039,877
Granted
Jan 13, 2026
Kind
B2
Abstract

In a general aspect, a network interface capable of processing network traffic conforming to a Time Sensitive Network (TSN) standard and a Media Access Control layer security (MACsec) standard, comprises, within an ingress path, a Physical Coding Sublayer (PCS) connected to receive a traffic stream from a network link; a Media Access Control (MAC) unit configured to split the traffic stream into a preemptable packet stream and an express packet stream; and a MACsec unit connected between the PCS and the MAC unit, configured to operate on individual fragments of a preempted MACsec protected packet in the traffic stream to produce a traffic stream with unprotected fragments for the MAC unit.

Claims (26)

1 . A hardware network interface capable of processing network traffic conforming to a Time Sensitive Network (TSN) standard and a Media Access Control layer security (MACsec) standard, comprising, within an ingress path:

a Physical Coding Sublayer (PCS) connected to receive a traffic stream from a network link;

a Media Access Control (MAC) controller including a selector that splits the traffic stream into a preemptable packet stream and an express packet stream; and

a MACsec processing pipeline between the PCS and the MAC controller along the ingress path, the MACsec processing pipeline to remove security tags from individual starting fragments of a preempted MACsec protected packets in the traffic stream to produce a traffic stream with unprotected fragments for the MAC unit, the MACsec processing pipeline to communicate, to the MAC controller, a small fragment signal based on sizes of corresponding unprotected fragments meeting a threshold, the MAC controller to accept corresponding unprotected fragments that meet the threshold based on the small fragment signal.

2 . The network interface of claim 1 , wherein

the MACsec processing pipeline is to insert trailing padding into start fragments of the size of the security tags, and to produce corresponding effective fragment length counts for the MAC controller; and

the MAC controller is to remove the trailing padding from the modified start fragments based on the corresponding effective fragment length counts.

3 . The network interface of claim 1 , wherein the MACsec processing pipeline further comprises:

a line a Media-Independent Interface (xMII) adapter coupled with the PCS; and

an system xMII adapter coupled with the MAC controller.

4 . A method for processing incoming network traffic according to a Time Sensitive Network (TSN) standard and a Media Access Control layer security (MACsec) standard, the incoming network traffic including at least one express packet interspersed with a plurality of fragments of a preempted MACsec protected packet, comprising:

receiving the incoming network traffic and processing the plurality of fragments by using protection information conveyed in the preempted MACsec protected packet, thereby producing a modified traffic stream conveying fragments of a preempted unprotected packet, the plurality of fragments including a starting fragment;

removing a security tag from the starting fragment to produce a shortened start fragment that, based on the removal of the security tag, meets a size threshold;

based on the shortened start fragment meeting the size threshold, signaling, in association with communicating the shortened start fragment, that the shortened start fragment that met the size threshold should be accepted as one of the plurality of fragments communicated as part of the modified stream; and

receiving the modified stream and splitting the modified stream into a preemptable packet stream in which the plurality of fragments are consolidated, and an express packet stream.

5 . The method of claim 4 , further comprising:

modifying the preempted MACsec protected packet by inserting trailing padding of the size of the security tag;

producing an effective fragment length count for the starting fragment; and

upon receiving the modified stream, responding to the effective fragment length count by removing the padding from the shortened start fragment.

6 . The method of claim 4 , further comprising:

receiving the incoming network stream in a Media-Independent Interface (xMII) format, and converting it to an intermediate format suitable for processing the protection information; and

converting the modified stream from the intermediate format back to the xMII format.

7 . A method for processing network traffic according to a Time Sensitive Network (TSN) standard and a Media Access Control layer security (MACsec) standard, comprising:

receiving a preemptable packet stream and a concurrent express packet stream via a single stream having at least one express packet interspersed with a plurality of fragments of a preempted packet, the plurality of fragments including a starting fragment having a size that, when a security tag is removed from the starting fragment to create a shortened starting fragment, meets a threshold;

based on the shortened starting fragment meeting the threshold, communicating, concurrently with communicating the shortened starting fragment and via a signal line not used to communicate the shortened starting fragment, a small fragment indicator; and

based on receiving the small fragment indicator, processing the shortened starting fragment for consolidation with others of the plurality of fragment to regenerate the preempted packet.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 1, 2023
From: DEMCHENKO, MAKSYM
To: RAMBUS INC.
Reel/Frame 063832/0783 →
Continuity (2)
Provisional Application 63123585 · Dec 10, 2020
Related Publication 20240007367A1 · Jan 4, 2024
References Cited (16)
US 6813729B1 · Tsang · 2004 [cited by examiner]
US 8635392B1 · Wang · 2014 [cited by applicant]
US 10523016B2 · Hacker · 2019 [cited by examiner]
US 20040001440A1 · Kostoff, II · 2004 [cited by examiner]
US 20100309932A1 · Diab et al. · 2010 [cited by applicant]
US 20110317587A1 · Lida et al. · 2011 [cited by applicant]
US 20130091349A1 · Chopra · 2013 [cited by applicant]
US 20130155929A1 · Aboul-Magd · 2013 [cited by examiner]
US 20140198780A1 · Qi · 2014 [cited by examiner]
US 20190238441A1 · Gotz et al. · 2019 [cited by applicant]
US 20220179997A1 · Branscomb · 2022 [cited by examiner]
Notification of Transmittal of the International Search Report and the Written Opinion of the International Searching Authority, or the Declaration with Mail Date Feb. 16, 2022 re: Int'l Appln. No. PCT/US2021/062576. 8 … [cited by applicant]
EP Extended European Search Report with Mail Date Sep. 25, 2024 re: EP Appln. No. 21904388.2. 11 pages. [cited by applicant]
Lackorzynski, Tim et al., “Enabling and Optimizing MACsec for Industrial Environments”, IEEE Transactions on Industrial Informatics, vol. 17, No. 11, Nov. 2021, XP011868414, ISSN: 1551-3203, DOI: 10.1109/TII.2020.304096… [cited by applicant]
McIntosh, James A., “MACsec-aware TSN Traffic Shapers”, IEEE Draft, vol. 802, Apr. 2015, XP068096440. 12 pages. [cited by applicant]
Weis, Brian, “A Proposal for Co-existence of MACsec and Priority/Pre-emption Features”, IEEE Draft, vol. 802.1, No. v00, Oct. 2014, SP068072021. 5 pages. [cited by applicant]